Skip to main content
A Quantum Group company Readiness only, never the assessment  ·  Boston  ·  London
Ashcroft Payment Security Get my estimate
PCI DSS compliance audit

Your bank set a deadline. Here is what a PCI DSS compliance audit really involves.

A PCI DSS compliance audit explained in plain words, with the prices published rather than hidden behind a form. Then, if you want it, a written estimate for getting ready, usually inside one business day.

Read this first. A formal PCI DSS compliance audit can only be performed by a Qualified Security Assessor, or QSA. We are not a QSA and we do not perform audits. What we do is get you ready for one, so that when your QSA arrives you pass. If you need a QSA, we will introduce you to one.

Five questions, about a minute. No phone number asked for, and no sales call.

What a PCI DSS compliance audit costs

Published US market ranges for a PCI DSS compliance audit in 2026. Almost nobody puts these on a page, but here they are.

Gap analysis and readiness$8,000 – $40,000
Remediation and implementation$30,000 – $150,000
Policy and documentation$10,000 – $30,000
QSA-led RoC audit$50,000 – $250,000
SAQ completion support$500 – $20,000
Quarterly ASV scanning$1,200 – $8,000
Annual penetration test$15,000 – $45,000
Typical Level 2 first year$85,000 – $190,000

The assessor's fee is only part of a PCI DSS compliance audit. Readiness and remediation are usually the larger half, because that is where the actual work happens.

Price my own scope
Trusted by

The teams we get through a PCI DSS compliance audit

Finance, engineering and compliance teams use us to arrive at their PCI DSS compliance audit prepared, so the assessor finds a tidy environment instead of a scramble.

  • ServiceNow logo, a client preparing for a PCI DSS compliance audit with Ashcroft
  • Accenture logo, a client preparing for a PCI DSS compliance audit with Ashcroft
  • Snowflake logo, a client preparing for a PCI DSS compliance audit with Ashcroft
  • MongoDB logo, a client preparing for a PCI DSS compliance audit with Ashcroft
  • Cloudflare logo, a client preparing for a PCI DSS compliance audit with Ashcroft
  • Atlassian logo, a client preparing for a PCI DSS compliance audit with Ashcroft
  • Plaid logo, a client preparing for a PCI DSS compliance audit with Ashcroft
  • Brex logo, a client preparing for a PCI DSS compliance audit with Ashcroft
  • Taimei Technology logo, a client preparing for a PCI DSS compliance audit with Ashcroft
  • symplr logo, a client preparing for a PCI DSS compliance audit with Ashcroft
  • Nebius logo, a client preparing for a PCI DSS compliance audit with Ashcroft
  • Tenovi logo, a client preparing for a PCI DSS compliance audit with Ashcroft

Logos are the property of their respective owners.

Start here

What a PCI DSS compliance audit actually is

Your bank sent a letter and it used a frightening phrase. So here is what a PCI DSS compliance audit actually means, without any jargon.

A PCI DSS compliance audit is an independent check of whether your business handles credit card data safely. So think of it like a health inspection for a restaurant, except the thing inspected is payment data rather than a kitchen.

The rules being checked are called PCI DSS. They were written by the card companies, and there are twelve of them. So a PCI DSS compliance audit works through those twelve, asks for evidence, and writes up what it finds.

The part that surprises most people is who does the inspecting. Only a Qualified Security Assessor can perform a formal PCI DSS compliance audit and sign the report your bank accepts. That is a licensed role, and it is not something any consultant can do, although plenty imply otherwise.

12
Requirements a PCI DSS compliance audit works through, one by one.
45%
Of businesses have failed an audit, so this is common rather than shameful.
3–6 mo
Typical time to fix what a gap analysis finds, which is why starting early matters.
$5,000
The lowest monthly fine for non-compliance, and it climbs from there.
Already overdue

Your PCI DSS compliance audit now includes 51 new requirements

The deadline for PCI DSS v4.0.1 was 31 March 2025. It has passed. Any assessment from that date onward has to include the new requirements, so a business that has not looked at this since 2024 is almost certainly non-compliant right now.

Requirement 6.4.3

Every script on your payment page

You now have to know exactly which scripts run on the page where customers type their card number, authorise each one, and prove none of them changed without you noticing.

Requirement 11.6.1

What a PCI DSS compliance audit now checks for tampering

You need something actively monitoring that payment page for unexpected changes. A firewall does not cover this, although a lot of businesses assume it does.

Requirement 8.4.2

Multi-factor on everything

Multi-factor authentication is now required for all access into the cardholder data environment, not just for administrators coming in from outside.

Two of those requirements were removed from SAQ A entirely. So if you have been relying on the shortest self-assessment form and assuming your payment provider covers scripts, that assumption is worth checking before your next PCI DSS compliance audit.

The licensed role

Who is allowed to perform a PCI DSS compliance audit

This is the most useful thing to understand before you spend money on a PCI DSS compliance audit. That is, it tells you what you are buying and from whom.

Who may produce each PCI document
DocumentPlain wordsWho may sign it
Report on ComplianceThe full audit report, often hundreds of pages.A QSA only. Internal assessors may sign for merchants, but never for service providers.
Attestation of ComplianceThe short summary you actually hand to your bank.A QSA plus your executive, or your executive alone on the self-assessment route.
Self-Assessment QuestionnaireA yes and no form you complete yourself.You do. A consultant may help you understand it, but your executive signs it.
ASV scan reportA quarterly scan of anything of yours facing the internet.Only a vendor on the official Approved Scanning Vendor list.

So the honest summary is short. In a PCI DSS compliance audit a QSA assesses and signs, while everyone else prepares, fixes and documents. Anyone who blurs that line is either careless or hoping you will not ask.

The sequence

What happens during a PCI DSS compliance audit

A PCI DSS compliance audit runs in six stages. Most businesses fail not because they are insecure, but because they were not ready for stage three.

Scoping your PCI DSS compliance audit

Working out which systems, people and processes touch card data. Because everything inside that boundary gets tested, this stage decides most of what a PCI DSS compliance audit costs.

Evidence gathering

Screenshots, configurations, logs, policies and records. This is where unprepared businesses lose weeks, since nobody collected anything in advance.

The PCI DSS compliance audit itself

Your assessor works through the requirements, interviews staff and examines what you handed over. They test, but they do not fix.

Findings

A list of anything that does not meet a requirement. However, a finding is not automatically a failure, provided you can close it in time.

Remediation

You fix what was found and produce fresh evidence. So the shorter this list is, the sooner the whole thing ends.

Closing the PCI DSS compliance audit

Your QSA writes the report and signs the attestation. That signed page is the thing your bank actually wanted all along.

Real numbers

What drives the price of a PCI DSS compliance audit

Nobody in this market publishes what a PCI DSS compliance audit costs. However, we think that is the wrong way round, so here is both the range and the reason behind it.

Price drivers ranked by impact
DriverHow much it moves the price
Transaction volumeBetween two and ten times. It sets your merchant level, and therefore whether a QSA is required at all.
Which form appliesBetween three and eight times. The shortest self-assessment is a few pages, but the longest runs past 300 questions.
Size of the card environmentUp to five times. Every extra system inside the boundary is another thing to test.
How you take paymentUp to three times. A hosted checkout is cheapest, while phone orders are the most expensive.
Network separationUp to double. Without it, your whole network is inside the boundary.
First time or renewalYear two typically costs 40 to 60 percent of year one, since the documentation already exists.
Watch the floor. Below $5,000 for anything involving remediation or QSA coordination is not real work. A penetration test under $8,000 is an automated scan, and a full report under $35,000 means the scope is unrealistic.
Book before October. Compliance work clusters in the last quarter and again before March, so rates and availability are both worse if you wait.
Self-check

Six signs you are not ready for a PCI DSS compliance audit

Each of these will cost you time in a PCI DSS compliance audit. Moreover, several of them will fail you outright.

One

No script inventory before your PCI DSS compliance audit

You cannot list every script running on your payment page. That is Requirement 6.4.3, and it is now mandatory.

Two

Nothing watching for changes

No monitoring alerts you when that payment page is modified. Requirement 11.6.1 asks for exactly this.

Three

Multi-factor only for admins

Requirement 8.4.2 now applies to all access into the card environment, so partial coverage is a finding.

Four

Treating the PCI DSS compliance audit as annual

One misconfigured port breaks it. Because v4.0.1 expects continuous evidence, an annual scramble no longer passes.

Five

Nobody can define the scope

If two people in your business draw the boundary differently, your PCI DSS compliance audit will find that immediately.

Six

Evidence lives in people's heads

If the proof exists but nobody has collected it, you will spend the assessment window hunting screenshots instead of passing.

Where we stop

What we do, and where your PCI DSS compliance audit begins

Most firms are vague about this. However, we would rather put it in a table, because the boundary is the whole point.

What Ashcroft does

  • Gap analysis against every applicable requirement
  • Scoping, and reducing that scope where we can
  • Remediation planning and hands-on implementation
  • Policies, procedures and the evidence package
  • Helping you understand and complete your own questionnaire
  • Introducing you to independent QSA firms, and coordinating with them

What Ashcroft never does

  • Perform the audit, or anything we would call an assessment
  • Sign a Report on Compliance or issue an attestation
  • Describe ourselves as a QSA, because we are not one
  • Run the quarterly scans, which need an approved vendor
  • Certify or validate anything, since that is a QSA function
  • Promise you will pass. Nobody honest can promise that.
Our work

How we prepare you for your PCI DSS compliance audit

Five stages of preparation before your PCI DSS compliance audit begins. So you always know which one you are in.

Scope and shrink

We map every path card data takes through your business, then look for ways to make that map smaller. Because scope drives cost, this stage usually pays for itself.

Gap analysis against every PCI DSS compliance audit requirement

We compare what you have against every requirement that applies to you, including the v4.0.1 additions, and hand you a prioritised list rather than a wall of text.

Remediation

We fix things with your team rather than handing over a report and leaving. So the awkward items get closed instead of postponed.

The evidence your PCI DSS compliance audit needs

We assemble the documentation your assessor will ask for, organised the way they expect it. This is where most of the assessment week is normally lost.

QSA handover

We work alongside your chosen assessor, or introduce you to one, and stay available while your PCI DSS compliance audit runs.

Where we are

Where your PCI DSS compliance audit support comes from

You contract with Ashcroft Payment Security wherever your engagement runs. Because the work is coordinated across US and UK hours, questions raised in the morning are usually answered the same working day.

Boston

Massachusetts, United States

1 Beacon Street
Boston, Massachusetts
United States

Eastern Time  ·  US engagements

London

United Kingdom

169 Piccadilly
London W1J 9EH
United Kingdom

Greenwich Mean Time  ·  UK and EU engagements

Straight answers

PCI DSS compliance audit questions buyers ask first

Do you perform the PCI DSS compliance audit yourselves?

No. Only a QSA can perform a formal PCI DSS compliance audit and sign the report your bank will accept. We are not a QSA. We prepare you for the assessment, and we can introduce you to independent QSA firms when you are ready.

Can you certify us as compliant?

No, and nobody outside a QSA can. Certifying and validating are assessor functions. What we can do is close the gaps that would otherwise fail you, so the assessor finds very little to write up.

We use Stripe, so are we already compliant?

Not quite. Your processor's compliance covers their systems, but it does not cover your checkout page, your scripts, your logs or your staff. Requirements 6.4.3 and 11.6.1 are specifically yours. Using a hosted checkout shrinks the work a great deal, although it does not remove it.

PCI is not a law, so can anyone actually make us do it?

It is not a statute, but it is in the contract you signed with your bank to accept cards. Break that contract and your bank can fine you, raise your fees, or stop you processing altogether. In practice that is as binding as a law.

How much will our PCI DSS compliance audit cost?

A typical Level 2 e-commerce merchant spends between $85,000 and $190,000 across the whole first year, with the QSA fee being only part of it. Send us five answers and we will give you a range for your own scope, usually within one business day.

Can you guarantee we pass our PCI DSS compliance audit?

No, and walk away from anyone who says otherwise. Your assessor reaches their own independent conclusion. What we commit to is that the gaps we find are closed and the evidence is ready before they arrive.

What was the March 2025 deadline?

That was when the 51 future-dated requirements in PCI DSS v4.0.1 became mandatory. It has passed. So any assessment from that date has to include them, and businesses that have not revisited their controls since 2024 are usually non-compliant without realising it.

Why is there no phone number on this site?

Because five written questions tell us more about your scope than a discovery call would, and it also respects your time. Answer them and you get a written range back rather than a calendar link.

Get a number

Price your PCI DSS compliance audit prep in five questions

These five answers are what anyone needs to estimate PCI DSS compliance audit preparation. So we can send a range without putting you through a call first.

A written budget range by email, usually within one business day.
No sales calls, and no phone number requested.
If you only need a QSA and not us, we will say so plainly.
Answer “I do not know” freely. It is a normal answer here.
Step 1 of 2
1. How do you take card payments?

Pick the closest one. If several apply, pick the one you use most.

2. Roughly how many card transactions a year?

Three quick ones left. No phone number required.

3. How many systems or locations touch card data?
4. Is your payment network kept separate?

Meaning a firewall keeps the card systems apart from everything else.

5. Have you been assessed before?

We will email a rough budget range within one business day. No sales calls, and your details are never shared.

Five questions, one minute Get my estimate